Summary
Togoder Security scanned the Go package google.golang.org/protobuf@v1.36.12 on Oct 5, 2026. An AI review of 336 source files produced 4 medium, 18 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 22
Unsafe pointer manipulation
NPS-F5E18207575B
Extensive use of unsafe.Pointer and type punning to convert interfaces to raw pointers and directly manipulate memory (interfaceToPointer, atomicGetPointer, AtomicLoadPointer, AtomicInitializePointer, AtomicSetPointer). While these are legitimate low-level operations for the protobuf runtime, they bypass Go's type safety and could be misused.
Raw memory writes via unsafe pointers
NPS-7CFF55E259F0
AtomicLoadPointer and AtomicInitializePointer write directly through unsafe pointers passed in as parameters without bounds or validity verification, which is inherently dangerous if callers pass invalid addresses.
Unsafe pointer arithmetic
NPS-AC1F947B3F84
The code uses extensive unsafe.Pointer arithmetic to access memory within a protobuf presence bitmap. While this is likely part of the official Go protobuf library (as indicated by the copyright notice and package name), such low-level memory manipulation can lead to memory corruption, out-of-bounds reads/writes, or crashes if the provided indices or sizes are incorrect. This is a potential security concern, but not indicative of malicious intent.
Unsafe memory aliasing
NPS-1156E8A63724
The UnsafeString and UnsafeBytes functions use unsafe.String and unsafe.Slice to create zero-copy conversions between []byte and string. If the caller violates the immutability contract, this can lead to data races, memory corruption, or unintended mutation of supposedly immutable strings. The code explicitly warns about this, but the API is inherently unsafe.
unsafe package usage
NPS-FA5E110BFDD9
Uses the unsafe package for efficient string/byte slicing, which is typical in protobuf generated code for performance. No memory corruption or exploitation patterns present.
init function
NPS-01AECF470058
The file contains an init() function that registers protobuf types with the runtime. This is standard generated code from protoc-gen-go and does not perform any malicious actions such as network requests, file system manipulation, or dynamic code execution.
Insecure file permissions
NPS-FA05CE35DF7F
The code uses os.WriteFile with permission 0777 when writing corpus files to internal/fuzz/... directories. This grants world-writable permissions, which could allow other local users to tamper with generated fuzz corpus files. While this is a test-only utility not run automatically, overly permissive file permissions are a security concern.
External command execution
NPS-F0B2529434B7
The code executes external commands (git, go, protoc, diff) via os/exec. While these are legitimate development tools for code generation, executing external binaries can be a security concern if those binaries are compromised or if the PATH is manipulated.
Network access via external tools
NPS-C5D639F04EA5
While the Go code itself does not make network requests, it invokes 'go list -m' which may access module proxies, and 'protoc' could potentially fetch remote resources depending on configuration.
Environment variable access
NPS-2AD0940CE5CE
Reads environment variables PROTOBUF_ROOT and RUN_AS_PROTOC_PLUGIN. RUN_AS_PROTOC_PLUGIN is used to change program behavior, which could be exploited if an attacker can control the environment.
File system manipulation
NPS-8184A7972837
The code writes generated files to the repository directory and creates temporary directories. It also modifies .proto files by generating hybrid/opaque variants. This is expected for a code generator but involves broad file system access.
Process execution
NPS-48279C9C1E11
The code executes external commands via os/exec: git rev-parse --show-toplevel is invoked twice (in main and chdirRoot), and diff is executed in writeSource when not in -execute mode. These are standard development tooling invocations for a code generator, but they do rely on the environment's git and diff binaries being present and trustworthy.
Working directory change based on external command output
NPS-84C44875E53D
chdirRoot changes the process working directory based on the output of git rev-parse --show-toplevel. If the working directory is inside a malicious or attacker-controlled git repository tree, this could redirect subsequent file writes. However, paths written are relative and constrained to the repo, so impact is limited.
File system write with world/group-writable permissions
NPS-0594C09D9DA7
writeSource writes generated files with mode 0664 (group-writable), which is slightly more permissive than the typical 0644. While not inherently malicious, group-writable source files can be modified by other users in the same group and is a minor hygiene concern.
Import-time file access
NPS-1676D37C8663
The package computes a hash of the host binary using os.Executable() and os.Open() at package initialization time via a package-level variable. While this is a legitimate technique documented by the Go project for deterministic randomness, reading the executable file at import time is unusual and could be repurposed for fingerprinting. No data is exfiltrated and the file read is limited to the program's own binary.
init-time code execution
NPS-892914FFC659
The init() function runs at import time and unmarshals hardcoded edition defaults from a compiled-in byte slice (editiondefaults.Defaults). No external input, files, or network access is involved, and the code only performs protobuf decoding with bounded iteration.
Unchecked type assertion
NPS-AF7FB48581EE
UnmarshalField performs an unchecked type assertion msg.(protoreflect.ProtoMessage), which will panic if msg is not the expected type. This is a robustness issue, though not actively malicious.
unsafe pointer usage
NPS-B5BE4E4B065C
The file heavily uses the unsafe package for pointer arithmetic and type conversions. While this is a legitimate technique for performance-critical reflection code in Go, it bypasses type safety and can lead to memory corruption if used incorrectly. The code is part of the official Go protobuf library and appears to be an internal implementation detail rather than a malicious pattern.
Potential race condition
NPS-29205BC85E0B
The presence methods (e.g., PresentInCache, AnyPresent) use atomic loads but do not guarantee atomicity across multiple accesses or mutations, which could lead to data races if the bitmap is modified concurrently. The comment in LoadPresenceCache acknowledges that simultaneous mutation may cause inconsistent results. This is a correctness and security risk (e.g., time-of-check-time-of-use), but typical for performance-optimized code in a well-known library.
Lifetime management risk
NPS-358CCC542C7D
The Builder type allocates a byte buffer and returns strings via UnsafeString that reference slices of this buffer. If the Builder is reused or the buffer is reallocated, previously returned strings may become invalid or alias new data. This can cause subtle bugs and potential security issues if strings are used after the Builder's lifetime.
Code Generation / Initialization
NPS-6DE6EB592A8E
This file is an auto-generated Go protobuf descriptor (protoc-gen-go). It defines protobuf extension metadata and an init() function that registers the file descriptor. The init() function only performs idempotent registration and does not exhibit malicious behavior such as network access, filesystem manipulation, or command execution.
Environment Variable Reading
NPS-C82514EF79DA
The code reads the GOLANG_PROTOBUF_REGISTRATION_CONFLICT environment variable to control conflict handling policy. This is a documented and legitimate configuration mechanism, not credential harvesting.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/cmd/generate-corpus/main.go | medium | No malicious intent detected; the code is a legitimate test corpus generator for Go protobuf fuzzing, but uses overly permissive 0777 file permissions when writing output files. |
| internal/cmd/generate-protos/main.go | medium | This appears to be a legitimate protobuf code generation tool from the official Go protobuf repository, with only standard development tool interactions and no malicious behavior. |
| internal/cmd/generate-types/main.go | medium | This is a standard Go protobuf code generator that invokes git and diff via os/exec and writes generated files; no data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found, only benign but notable subprocess and file-write behaviors. |
| internal/impl/api_export_opaque.go | medium | This is a legitimate protobuf internal export shim using unsafe pointer operations and atomics for runtime support, with no evidence of exfiltration, credential harvesting, shell execution, or other malicious patterns, though its heavy use of unsafe memory manipulation warrants caution. |
| internal/impl/presence.go | medium | The code is part of the official Go protobuf library and uses unsafe pointer arithmetic and atomic operations for performance, posing potential memory safety and race condition risks, but no malicious patterns were detected. |
| internal/strs/strings_unsafe.go | medium | The code uses unsafe memory operations for performance, which introduces aliasing and lifetime risks but contains no malicious patterns such as exfiltration, backdoors, or code execution. |
| cmd/protoc-gen-go/internal_gengo/init.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/protoc-gen-go/internal_gengo/init_opaque.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/protoc-gen-go/internal_gengo/main.go | safe | This is a legitimate protobuf code generator file with no malicious patterns detected. |
| cmd/protoc-gen-go/internal_gengo/opaque.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/protoc-gen-go/internal_gengo/reflect.go | safe | This is standard Go protobuf code generation logic with no malicious patterns; generated init() functions only initialize protobuf descriptors as intended. |
| cmd/protoc-gen-go/internal_gengo/well_known_types.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/protoc-gen-go/main.go | safe | No malicious patterns detected; this is the standard protoc-gen-go protobuf plugin entry point with no network, filesystem, or process manipulation beyond expected code generation. |
| cmd/protoc-gen-go/testdata/annotations/annotations.pb.go | safe | No malicious patterns detected in this protoc-gen-go generated test data file. |
| cmd/protoc-gen-go/testdata/comments/comments.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns, network calls, process execution, or credential access. |
| cmd/protoc-gen-go/testdata/comments/deprecated.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns; initialization code only sets up protobuf type descriptors using the standard protobuf runtime. |
| cmd/protoc-gen-go/testdata/enumprefix/enumprefix.pb.go | safe | No malicious patterns detected; this is standard generated protobuf code for a test data enum prefix package. |
| cmd/protoc-gen-go/testdata/extensions/base/base.pb.go | safe | No malicious patterns detected in this standard protobuf-generated Go file. |
| cmd/protoc-gen-go/testdata/extensions/ext/ext.pb.go | safe | No malicious patterns detected in this generated protobuf Go file; it contains only standard protoc-gen-go output with no network, filesystem, process, or dynamic code execution activity. |
| cmd/protoc-gen-go/testdata/extensions/extra/extra.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/extensions/proto3/ext3.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code containing only type definitions, extension metadata, and descriptor initialization. |
| cmd/protoc-gen-go/testdata/featureresolution/basic.pb.go | safe | This is a standard protoc-gen-go generated protobuf file for test data, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or suspicious network/process activity. |
| cmd/protoc-gen-go/testdata/features/test_features.pb.go | safe | No malicious patterns detected; this is standard generated protobuf code with no network, filesystem, process execution, or obfuscated behavior. |
| cmd/protoc-gen-go/testdata/fieldnames/fieldnames.pb.go | safe | This is auto-generated protobuf Go code from the official Go toolchain testdata with no malicious patterns; the init() function only performs standard protobuf type registration. |
| cmd/protoc-gen-go/testdata/import_option/import_option.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code containing only protobuf message definitions and initialization logic. |
Show 311 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| cmd/protoc-gen-go/testdata/import_option_custom/import_option_custom.pb.go | safe | No malicious patterns detected in the generated protobuf Go code. |
| cmd/protoc-gen-go/testdata/import_option_unlinked/import_option_unlinked.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with only init-time TypeBuilder registration and no network, filesystem, process, or obfuscated behavior. |
| cmd/protoc-gen-go/testdata/import_public/a.pb.go | safe | This is standard protoc-gen-go generated Go code for protobuf testdata with no malicious patterns, network calls, credential access, or dynamic execution. |
| cmd/protoc-gen-go/testdata/import_public/b.pb.go | safe | Generated protobuf Go code with no malicious patterns; only standard protobuf runtime usage and initialization. |
| cmd/protoc-gen-go/testdata/import_public/c.pb.go | safe | No malicious patterns detected; this is a standard generated protobuf file with no network, filesystem, process, or dynamic code execution activity. |
| cmd/protoc-gen-go/testdata/import_public/sub/a.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/import_public/sub/b.pb.go | safe | No malicious patterns detected in this generated protobuf Go source file |
| cmd/protoc-gen-go/testdata/import_public/sub2/a.pb.go | safe | This is a standard protoc-gen-go generated file with only protobuf runtime code and no malicious patterns. |
| cmd/protoc-gen-go/testdata/imports/fmt/m.pb.go | safe | This is auto-generated protobuf Go code from the official Google protobuf repository, containing only standard message registration and descriptor code with no malicious patterns. |
| cmd/protoc-gen-go/testdata/imports/test_a_1/m1.pb.go | safe | Generated protobuf Go code with no malicious patterns detected; contains only standard protobuf runtime initialization and descriptor handling. |
| cmd/protoc-gen-go/testdata/imports/test_a_1/m2.pb.go | safe | This is standard protoc-gen-go generated code with no malicious patterns, network calls, process execution, or credential access. |
| cmd/protoc-gen-go/testdata/imports/test_a_2/m3.pb.go | safe | This is a standard protoc-gen-go generated file from the official Go protobuf repository containing only benign message type definitions and initialization code with no malicious patterns. |
| cmd/protoc-gen-go/testdata/imports/test_a_2/m4.pb.go | safe | Auto-generated protobuf Go code with only standard init-time registration and no malicious patterns |
| cmd/protoc-gen-go/testdata/imports/test_b_1/m1.pb.go | safe | This is standard machine-generated protobuf code from the official Go protobuf repository with no malicious patterns; the init() function only registers the message type descriptor. |
| cmd/protoc-gen-go/testdata/imports/test_b_1/m2.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code for a test message with no network, filesystem, process, or dynamic execution activity. |
| cmd/protoc-gen-go/testdata/imports/test_import_a1m1.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/imports/test_import_a1m2.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with no network, filesystem, process, or credential access. |
| cmd/protoc-gen-go/testdata/imports/test_import_all.pb.go | safe | No malicious patterns detected; this is standard generated protobuf code from the official Go protobuf module with no network, filesystem, process, or obfuscated behavior. |
| cmd/protoc-gen-go/testdata/issue780_oneof_conflict/test.pb.go | safe | Generated protobuf Go code for the Go standard library testdata; contains only standard serialization logic with no malicious patterns. |
| cmd/protoc-gen-go/testdata/nameclash/nameclash.go | safe | Cleared by Jev triage; no further analysis needed |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid/test_name_clash_hybrid.pb.go | safe | This is standard, protoc-gen-go generated Go code from the official Google protobuf repository containing no malicious patterns, network calls, credential harvesting, dynamic code execution, or suspicious process spawning. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid/test_name_clash_hybrid_protoopaque.pb.go | safe | This is generated protobuf Go code with only standard protoimpl/reflect/unsafe usage and no network, filesystem, process, or obfuscated behavior. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_hybrid3/test_name_clash_hybrid3_protoopaque.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated test file for name clash handling. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_opaque/test_name_clash_opaque.pb.go | safe | Generated protobuf test code contains only standard serialization/deserialization logic with no malicious patterns, network calls, or dynamic execution. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_opaque3/test_name_clash_opaque3.pb.go | safe | Generated protobuf test data code contains no suspicious network, filesystem, process, or obfuscated logic. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_open/test_name_clash_open.pb.go | safe | This is a standard protoc-gen-go generated file from the official Go protobuf repository containing only message definitions, getters, and descriptor initialization with no malicious patterns. |
| cmd/protoc-gen-go/testdata/nameclash/test_name_clash_open3/test_name_clash_open3.pb.go | safe | This is an autogenerated protobuf Go test fixture with no malicious patterns, network calls, exec/spawn logic, or sensitive data access. |
| cmd/protoc-gen-go/testdata/nopackage/nopackage.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/proto2/enum.pb.go | safe | This is standard auto-generated protobuf Go code with no malicious patterns, network activity, credential access, or dynamic execution detected. |
| cmd/protoc-gen-go/testdata/proto2/fields.pb.go | safe | This is standard generated protobuf code with no malicious patterns detected. |
| cmd/protoc-gen-go/testdata/proto2/nested_messages.pb.go | safe | This is standard generated protobuf Go code from the official google.golang.org/protobuf repository with no malicious patterns or security concerns. |
| cmd/protoc-gen-go/testdata/proto2/proto2.pb.go | safe | This is standard auto-generated protobuf Go code with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning. |
| cmd/protoc-gen-go/testdata/proto3/enum.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with only benign init-time registration. |
| cmd/protoc-gen-go/testdata/proto3/fields.pb.go | safe | No malicious patterns detected; this is a standard auto-generated protobuf Go file with no network, filesystem, process execution, or obfuscated code. |
| cmd/protoc-gen-go/testdata/protoeditions/enum.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file with only benign serialization and enum initialization code. |
| cmd/protoc-gen-go/testdata/protoeditions/fields.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated protobuf code with no network, filesystem, process, or obfuscation activity. |
| cmd/protoc-gen-go/testdata/protoeditions/legacy_enum.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/protoeditions/maps_and_delimited.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code from the official Go protobuf repository with no network, filesystem, process, or obfuscated behavior. |
| cmd/protoc-gen-go/testdata/protoeditions/nested_messages.pb.go | safe | This is standard protoc-gen-go generated code for nested protobuf messages with no malicious patterns, network activity, obfuscation, or credential access. |
| cmd/protoc-gen-go/testdata/retention/options_message.pb.go | safe | No malicious patterns detected |
| cmd/protoc-gen-go/testdata/retention/retention.pb.go | safe | This is an automatically generated Go protobuf file from the official Go protobuf module containing only standard protobuf type definitions, reflection metadata, and initialization code with no malicious patterns. |
| cmd/protoc-gen-go/testdata/visibility/visibility.pb.go | safe | This is standard protoc-gen-go generated code with no malicious patterns, network activity, or obfuscation. |
| compiler/protogen/protogen.go | safe | No malicious patterns detected in the protogen package source; it is a standard Go protobuf code generator with expected file and network-adjacent operations limited to reading stdin/stdout and filesystem paths. |
| compiler/protogen/protogen_apilevel.go | safe | Cleared by Jev triage; no further analysis needed |
| compiler/protogen/protogen_opaque.go | safe | No malicious patterns detected; the code is a legitimate protobuf code generator helper with no network, filesystem, process, or dynamic execution activity. |
| encoding/protodelim/protodelim.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/protojson/decode.go | safe | No malicious patterns detected; this is the standard Go protobuf JSON decoder implementation from the official google.golang.org/protobuf module. |
| encoding/protojson/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/protojson/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/protojson/well_known_types.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/prototext/decode.go | safe | No malicious patterns detected |
| encoding/prototext/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/prototext/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| encoding/protowire/wire.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/cmd/generate-types/impl.go | safe | This is a legitimate protobuf code generation file using Go templates to produce wire encoding/decoding functions; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, crypto mining, backdoors, suspicious network activity, filesystem manipulation, or process spawning were detected. |
| internal/cmd/generate-types/impl_opaque.go | safe | No malicious patterns detected |
| internal/cmd/generate-types/proto.go | safe | No malicious patterns detected; the file contains legitimate protobuf wire type and Go type definitions used for generating serialization code. |
| internal/cmd/pbdump/pbdump.go | safe | The code is a legitimate debugging tool from the Go protobuf repository that reads and decodes protocol buffer messages without any malicious patterns. |
| internal/descfmt/stringer.go | safe | No malicious patterns detected; the code is a legitimate protobuf descriptor formatter with no network, filesystem, credential, or execution-related concerns. |
| internal/descopts/options.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/detrand/rand.go | safe | The code is a legitimate Go standard-library-style package for deterministic randomness; it reads its own executable at init but performs no network, process, credential, or other malicious activity. |
| internal/editiondefaults/defaults.go | safe | No malicious patterns detected; the file only embeds a static binary defaults file with no execution, network, or credential access. |
| internal/editionssupport/editions.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/defval/default.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/json/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/json/decode_number.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/json/decode_string.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/json/decode_token.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/json/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/messageset/messageset.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/tag/tag.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/decode_number.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/decode_string.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/decode_token.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/encoding/text/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/errors/errors.go | safe | No malicious patterns detected |
| internal/filedesc/build.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/desc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/desc_init.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/desc_lazy.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/desc_list.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/desc_list_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/editions.go | safe | This file is part of the official google.golang.org/protobuf module and contains only protobuf feature-set parsing logic with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or external command execution. |
| internal/filedesc/placeholder.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filedesc/presence.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/filetype/build.go | safe | No malicious patterns detected |
| internal/flags/flags.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/flags/proto_legacy_disable.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/flags/proto_legacy_enable.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/fuzz/jsonfuzz/fuzz.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/fuzz/textfuzz/fuzz.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/fuzz/wirefuzz/fuzz.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/fuzztest/fuzztest.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/any_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/api_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/descriptor_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/duration_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/empty_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/field_mask_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/go_features_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/goname.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/map_entry.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/name.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/source_context_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/struct_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/timestamp_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/type_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/wrappers.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/genid/wrappers_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/api_export.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/bitmap.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/bitmap_race.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/checkinit.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_extension.go | safe | No malicious patterns detected |
| internal/impl/codec_field.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_field_opaque.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_map.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_message.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_message_opaque.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_messageset.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_tables.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/codec_unsafe.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/convert.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/convert_list.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/convert_map.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/decode.go | safe | No malicious patterns detected in this protobuf decoding implementation. |
| internal/impl/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/enum.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/equal.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/extension.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/lazy.go | safe | The code is a legitimate part of the Go protobuf library implementing lazy unmarshaling; it contains no malicious patterns such as data exfiltration, credential harvesting, backdoors, or suspicious network/process activity. |
| internal/impl/legacy_enum.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/legacy_export.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/legacy_extension.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/legacy_file.go | safe | No malicious patterns detected; the code is a legitimate part of the Go protobuf library for loading legacy file descriptors with gzip decompression and caching. |
| internal/impl/legacy_message.go | safe | This file is part of the official Go protobuf runtime (google.golang.org/protobuf) and contains only legitimate legacy message reflection/wrapping logic with no malicious patterns. |
| internal/impl/merge.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/merge_gen.go | safe | No malicious patterns detected |
| internal/impl/message.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_opaque.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_opaque_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_reflect.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_reflect_field.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_reflect_field_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/message_reflect_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/impl/pointer_unsafe.go | safe | No malicious patterns detected; the code uses unsafe pointer operations for performance but is part of the official Go protobuf library. |
| internal/impl/pointer_unsafe_opaque.go | safe | No malicious patterns detected |
| internal/impl/validate.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/msgfmt/format.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/order/order.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/order/range.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pragma/pragma.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/protobuild/build.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/protolazy/bufferreader.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/protolazy/lazy.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/protolazy/pointer_unsafe.go | safe | No malicious patterns detected |
| internal/protolegacy/proto.go | safe | No malicious patterns detected in this legacy protocol stub implementation. |
| internal/set/ints.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/strs/strings.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testprotos/annotation/annotation.pb.go | safe | Generated protobuf code for an internal test annotation with no malicious patterns, network activity, or dynamic execution. |
| internal/testprotos/benchmarks/benchmarks.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for benchmark protobuf definitions. |
| internal/testprotos/benchmarks/datasets/google_message1/proto2/benchmark_message1_proto2.pb.go | safe | This is a standard protoc-gen-go generated file for benchmark protobuf messages with no malicious patterns, dynamic execution, network activity, or filesystem manipulation. |
| internal/testprotos/benchmarks/datasets/google_message1/proto3/benchmark_message1_proto3.pb.go | safe | No malicious patterns detected in this generated protobuf file; it contains only standard boilerplate message definitions and initialization code. |
| internal/testprotos/benchmarks/datasets/google_message2/benchmark_message2.pb.go | safe | This is a standard protoc-gen-go generated file for benchmark protobuf messages with no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| internal/testprotos/benchmarks/datasets/google_message3/benchmark_message3_7.pb.go | safe | This is a standard protoc-gen-go generated file containing only Protocol Buffer message definitions with no malicious activity, network operations, or suspicious behavior. |
| internal/testprotos/benchmarks/micro/micro.pb.go | safe | No malicious patterns detected; the file is standard generated protobuf Go code with no network, filesystem, process, or dynamic execution activity. |
| internal/testprotos/conformance/conformance.pb.go | safe | This is a standard protoc-generated Go file for Protocol Buffers conformance testing with no malicious patterns, external calls, or suspicious behavior. |
| internal/testprotos/conformance/editions/test_messages_edition2023.pb.go | safe | This is a standard protoc-gen-go generated file from the official Google Protocol Buffers repository containing no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| internal/testprotos/conformance/editionsmigration/test_messages_proto3_editions.pb.go | safe | This is a standard protoc-gen-go generated Go file for a test protobuf schema with no malicious patterns, network activity, credential access, or dynamic code execution. |
| internal/testprotos/conformance/editionunstable/test_messages_edition_unstable.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code with normal init registration and no network, filesystem, process, or dynamic-execution activity. |
| internal/testprotos/conformance/test_messages_proto3.pb.go | safe | No malicious patterns detected in this protoc-generated Go file, which contains only standard protobuf message definitions, getters, and reflection metadata. |
| internal/testprotos/editionsfuzztest/test2.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for protocol buffer test types. |
| internal/testprotos/editionsfuzztest/test2editions.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for protobuf test messages with no network, filesystem, process, or dynamic execution activity. |
| internal/testprotos/editionsfuzztest/test3.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with no network, exec, filesystem, or obfuscated behavior. |
| internal/testprotos/editionsfuzztest/test3editions.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for protobuf test messages with no network, filesystem, process, or dynamic execution behavior. |
| internal/testprotos/enums/enums.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file containing only enum definitions and protobuf registration logic. |
| internal/testprotos/enums/enums_hybrid/enums.hybrid.pb.go | safe | Auto-generated Go protobuf enum code with only standard protobuf runtime initialization and no malicious patterns detected |
| internal/testprotos/enums/enums_hybrid/enums.hybrid_protoopaque.pb.go | safe | This is a standard protoc-gen-go generated file containing only enum definitions and protobuf descriptor registration with no malicious patterns. |
| internal/testprotos/enums/enums_opaque/enums.opaque.pb.go | safe | Generated protobuf enum code with standard init-time descriptor registration and no malicious patterns detected |
| internal/testprotos/examples/ext/extexample.pb.go | safe | Generated protobuf Go code with no malicious patterns; only standard protobuf runtime initialization, no network, filesystem, process execution, or obfuscated behavior. |
| internal/testprotos/fieldtrack/fieldtrack.pb.go | safe | Generated protobuf code from the official Go protobuf repository containing only standard serialization logic and no malicious patterns. |
| internal/testprotos/fuzz/fuzz.pb.go | safe | Code is auto-generated protobuf Go source from the official google.golang.org/protobuf repository with no malicious patterns detected |
| internal/testprotos/irregular/irregular.go | safe | No malicious patterns detected; the code is a legitimate protobuf internal test fixture from the Go standard library's protobuf repository. |
| internal/testprotos/irregular/test.pb.go | safe | No malicious patterns detected; this is standard generated Go protobuf code from the official Go protobuf module. |
| internal/testprotos/lazy/lazy_extension_normalized_wire_test.pb.go | safe | Generated protobuf Go code with no malicious patterns detected |
| internal/testprotos/lazy/lazy_extension_test.pb.go | safe | No malicious patterns detected; this is standard generated Go protobuf code with no network, exec, or filesystem activity. |
| internal/testprotos/lazy/lazy_hybrid/lazy_tree.hybrid.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with only serialization, accessor, and builder logic. |
| internal/testprotos/lazy/lazy_hybrid/lazy_tree.hybrid_protoopaque.pb.go | safe | This is standard generated Go protobuf code from the official google.golang.org/protobuf repository with no malicious patterns detected. |
| internal/testprotos/lazy/lazy_normalized_wire_test.pb.go | safe | This is a standard protoc-gen-go generated file from the Go protobuf repository containing only message type definitions and reflection metadata, with no malicious patterns detected. |
| internal/testprotos/lazy/lazy_opaque/lazy_tree.opaque.pb.go | safe | No malicious patterns detected in this auto-generated protobuf message code for the lazy_opaque test package. |
| internal/testprotos/lazy/lazy_tree.pb.go | safe | This is a standard protocol buffer generated Go file with no malicious patterns detected. |
| internal/testprotos/legacy/bug1052/bug1052.pb.go | safe | This is an auto-generated protobuf Go file that only registers enums, extensions, and file descriptors with no malicious patterns. |
| internal/testprotos/legacy/legacy.pb.go | safe | No malicious patterns detected; this is standard auto-generated protobuf Go code with no network, filesystem, process, or dynamic execution activity. |
| internal/testprotos/legacy/proto3_20160225_2fc053c5/test.pb.go | safe | The code is a standard auto-generated Go protobuf file containing only message definitions, serialization logic, and an init() function for type registration; no malicious patterns found. |
| internal/testprotos/legacy/proto3_20160519_a4ab9ec5/test.pb.go | safe | No malicious patterns detected in this generated protobuf Go file. |
| internal/testprotos/legacy/proto3_20180125_92554152/test.pb.go | safe | No malicious patterns detected |
| internal/testprotos/legacy/proto3_20180430_b4deda09/test.pb.go | safe | No malicious patterns detected |
| internal/testprotos/legacy/proto3_20180814_aa810b61/test.pb.go | safe | This is an auto-generated protobuf Go file containing only standard message definitions, getters, and marshaling code, with no malicious patterns detected. |
| internal/testprotos/legacy/proto3_20190205_c823c79e/test.pb.go | safe | Generated protobuf Go code with standard init and registration functions; no malicious patterns detected. |
| internal/testprotos/messageset/messagesetpb/message_set.pb.go | safe | No malicious patterns detected; the file is standard generated Go protobuf code with no network, filesystem, process, or credential access. |
| internal/testprotos/messageset/messagesetpb/messagesetpb_hybrid/message_set.hybrid.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code from the official Go protobuf module. |
| internal/testprotos/messageset/messagesetpb/messagesetpb_hybrid/message_set.hybrid_protoopaque.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code from Google's official protobuf module. |
| internal/testprotos/messageset/messagesetpb/messagesetpb_opaque/message_set.opaque.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with no network, filesystem, process, or dynamic execution behavior. |
| internal/testprotos/messageset/msetextpb/msetextpb.pb.go | safe | Generated protobuf Go code contains only standard serialization boilerplate with no malicious patterns such as exfiltration, credential harvesting, or code execution. |
| internal/testprotos/messageset/msetextpb/msetextpb_hybrid/msetextpb.hybrid.pb.go | safe | Generated protobuf Go file contains only standard message boilerplate with no malicious patterns detected |
| internal/testprotos/messageset/msetextpb/msetextpb_hybrid/msetextpb.hybrid_protoopaque.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns detected. |
| internal/testprotos/messageset/msetextpb/msetextpb_opaque/msetextpb.opaque.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file from the official Go protobuf module containing only message definitions, extensions, and init-time registration with no network, filesystem, process, or obfuscated code. |
| internal/testprotos/mixed/mixed.pb.go | safe | This is a standard protoc-gen-go generated test file for protobuf messages with no malicious patterns, network activity, or obfuscated code. |
| internal/testprotos/news/news.pb.go | safe | No malicious patterns detected in this auto-generated protobuf Go code, which only contains standard message definitions and serialization logic. |
| internal/testprotos/nullable/nullable.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/testprotos/order/order.pb.go | safe | This is a standard protoc-gen-go generated file with only benign protobuf message/extension definitions and initialization code, no malicious patterns detected. |
| internal/testprotos/race/extender/test.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for a protobuf test proto file. |
| internal/testprotos/race/message/test.pb.go | safe | This is standard generated protobuf Go code from the official google.golang.org/protobuf module with no malicious patterns, no network/file/process activity, and no dynamic code execution. |
| internal/testprotos/registry/test.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with only init-time registration and no network, filesystem, or process operations. |
| internal/testprotos/required/required.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with no network, filesystem, process, or dynamic execution behavior. |
| internal/testprotos/required/required_hybrid/required.hybrid.pb.go | safe | This is protoc-gen-go generated code containing only standard protobuf message definitions, accessors, and registration logic with no malicious patterns. |
| internal/testprotos/required/required_hybrid/required.hybrid_protoopaque.pb.go | safe | This is an auto-generated protobuf Go file from a trusted internal test package with no malicious patterns detected. |
| internal/testprotos/required/required_opaque/required.opaque.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code for opaque API test protos. |
| internal/testprotos/test3/test.pb.go | safe | Generated protobuf Go code contains no malicious patterns, no network activity, no credential harvesting, and no dynamic code execution. |
| internal/testprotos/test3/test3_hybrid/test.hybrid.pb.go | safe | Generated Go protobuf code from a test package contains no malicious patterns. |
| internal/testprotos/test3/test3_hybrid/test.hybrid_protoopaque.pb.go | safe | This is a standard protoc-gen-go generated file for a test protobuf message; it contains only generated boilerplate with no malicious patterns, no network/file/process operations, and no dynamic code execution. |
| internal/testprotos/test3/test3_hybrid/test_import.hybrid.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns detected. |
| internal/testprotos/test3/test3_hybrid/test_import.hybrid_protoopaque.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns; all code is typical protobuf runtime initialization and contains no network, filesystem, process, or dynamic execution activity. |
| internal/testprotos/test3/test3_opaque/test.opaque.pb.go | safe | This is an auto-generated protobuf Go file from google.golang.org/protobuf internal test protos, containing only standard generated serialization code with no malicious patterns such as network calls, command execution, credential harvesting, or obfuscated payloads. |
| internal/testprotos/test3/test3_opaque/test_import.opaque.pb.go | safe | Generated protobuf Go code with no malicious patterns; only standard protobuf descriptor initialization and type definitions. |
| internal/testprotos/test3/test_extension.pb.go | safe | Auto-generated protobuf descriptor file with a standard init() registration; no malicious patterns detected. |
| internal/testprotos/test3/test_import.pb.go | safe | This is a standard protoc-gen-go generated file for the official Go protobuf library, containing only protobuf enum/message definitions and descriptor registration with no suspicious behavior. |
| internal/testprotos/testeditions/test_extension.pb.go | safe | This is standard generated protoc-gen-go code from the official Go protobuf module, containing no malicious patterns, network activity, or dynamic code execution. |
| internal/testprotos/testeditions/test_extension2.pb.go | safe | No malicious patterns detected; this is standard generated protobuf Go code with no network, file system, process execution, or obfuscated content. |
| internal/testprotos/testeditions/test_import.pb.go | safe | No malicious patterns detected |
| internal/testprotos/testeditions/testeditions_hybrid/test_extension.hybrid.pb.go | safe | No malicious patterns detected in this generated protobuf Go file. |
| internal/testprotos/testeditions/testeditions_hybrid/test_extension.hybrid_protoopaque.pb.go | safe | Generated protobuf Go code contains only standard message/extension definitions and init() registration with no malicious patterns, network activity, or external command execution. |
| internal/testprotos/testeditions/testeditions_hybrid/test_extension2.hybrid.pb.go | safe | No malicious patterns detected; this is generated protobuf Go code with standard initialization and no external I/O, credential access, or dynamic execution. |
| internal/testprotos/testeditions/testeditions_hybrid/test_extension2.hybrid_protoopaque.pb.go | safe | No malicious patterns detected; the file is standard generated Go protobuf code with no network, filesystem, process, or dynamic execution behavior. |
| internal/testprotos/testeditions/testeditions_hybrid/test_import.hybrid.pb.go | safe | This is standard generated protobuf Go code with no malicious patterns, network activity, credential access, or dynamic execution. |
| internal/testprotos/testeditions/testeditions_hybrid/test_import.hybrid_protoopaque.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for a test protobuf message with no network, filesystem, process, or obfuscation concerns. |
| internal/testprotos/testeditions/testeditions_opaque/test_extension.opaque.pb.go | safe | This is an auto-generated protobuf Go file from the standard Google protobuf library; it contains no network, file system, process, or dynamic execution code. |
| internal/testprotos/testeditions/testeditions_opaque/test_extension2.opaque.pb.go | safe | This is auto-generated Go protobuf code with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or network/process manipulation. |
| internal/testprotos/testeditions/testeditions_opaque/test_import.opaque.pb.go | safe | No malicious patterns detected; the file is a standard protoc-gen-go generated source with only benign initialization and descriptor registration. |
| internal/testprotos/textpb2/test.pb.go | safe | This is standard protoc-gen-go generated code for protobuf test messages with no malicious patterns, network calls, file system access, or dynamic execution. |
| internal/testprotos/textpb3/test.pb.go | safe | This is a standard protoc-gen-go generated file for protobuf test definitions with no malicious patterns, network calls, credential access, or dynamic code execution. |
| internal/testprotos/textpbeditions/test2.pb.go | safe | Generated protobuf Go code with no malicious patterns, network calls, or dynamic execution detected. |
| internal/version/version.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/weakdeps/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/weakdeps/weakdeps.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/checkinit.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/decode_gen.go | safe | No malicious patterns detected |
| proto/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/encode.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/encode_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/equal.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/extension.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/merge.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/messageset.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/proto.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/proto_methods.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/proto_reflect.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/reset.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/size.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/size_gen.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/wrapperopaque.go | safe | Cleared by Jev triage; no further analysis needed |
| proto/wrappers.go | safe | Cleared by Jev triage; no further analysis needed |
| protoadapt/convert.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protodesc/desc.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protodesc/desc_init.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protodesc/desc_resolve.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protodesc/desc_validate.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protodesc/editions.go | safe | No malicious patterns detected; the code is part of the official Google protobuf-go library and performs normal descriptor initialization and feature merging without any suspicious behavior. |
| reflect/protodesc/proto.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protopath/path.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protopath/step.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protorange/range.go | safe | No malicious patterns detected; the code is part of the official Go protobuf library providing message traversal functionality without network, filesystem, or process manipulation. |
| reflect/protoreflect/methods.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/proto.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/source.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/source_gen.go | safe | No malicious patterns detected; the file contains generated code for protobuf source path handling with no network, filesystem, or dynamic execution behavior. |
| reflect/protoreflect/type.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/value.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/value_equal.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/value_union.go | safe | Cleared by Jev triage; no further analysis needed |
| reflect/protoreflect/value_unsafe.go | safe | No malicious patterns detected; the file contains standard unsafe pointer utilities for the Go protobuf runtime. |
| reflect/protoregistry/registry.go | safe | This is the standard Go protobuf registry implementation; the only environment variable read is for documented conflict policy configuration, with no malicious patterns detected. |
| runtime/protoiface/legacy.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/protoiface/methods.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/protoimpl/impl.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/protoimpl/version.go | safe | Cleared by Jev triage; no further analysis needed |
| runtime/protolazy/protolazy.go | safe | No malicious patterns detected; the code only exposes a toggle for protobuf lazy unmarshaling with no network, filesystem, environment, or process activity. |
| testing/protocmp/reflect.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/protocmp/util.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/protocmp/xform.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/protopack/pack.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/prototest/enum.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/prototest/message.go | safe | Cleared by Jev triage; no further analysis needed |
| types/dynamicpb/dynamic.go | safe | Cleared by Jev triage; no further analysis needed |
| types/dynamicpb/types.go | safe | Cleared by Jev triage; no further analysis needed |
| types/gofeaturespb/go_features.pb.go | safe | This is a standard protoc-gen-go generated file from Google's official protobuf repository containing only enum definitions, message types, and descriptor initialization with no malicious patterns. |
| types/known/anypb/any.pb.go | safe | No malicious patterns detected; code is a standard generated Go protobuf file from the official google.golang.org/protobuf package with no suspicious behavior. |
| types/known/apipb/api.pb.go | safe | This is a standard, auto-generated Protocol Buffers Go file from the official Google protobuf library with no malicious patterns. |
| types/known/durationpb/duration.pb.go | safe | No malicious patterns detected |
| types/known/emptypb/empty.pb.go | safe | No malicious patterns detected |
| types/known/fieldmaskpb/field_mask.pb.go | safe | No malicious patterns detected; this is a standard generated Protocol Buffers FieldMask implementation with no network, filesystem, process, or credential access. |
| types/known/sourcecontextpb/source_context.pb.go | safe | No malicious patterns detected |
| types/known/structpb/struct.pb.go | safe | This is a standard generated Protocol Buffers Go file from Google's official protobuf-go package; no malicious patterns, suspicious imports, network activity, or obfuscated code were detected. |
| types/known/timestamppb/timestamp.pb.go | safe | This is a standard, generated Protocol Buffers Timestamp type from Google's official protobuf-go library with no malicious patterns detected. |
| types/known/typepb/type.pb.go | safe | No malicious patterns detected; this is standard generated protobuf code from the official Google Protobuf Go library with no exfiltration, obfuscation, dynamic execution, or suspicious behavior. |
| types/known/wrapperspb/wrappers.pb.go | safe | No malicious patterns detected in this generated Protocol Buffers wrapper code from Google's official protobuf-go library. |
| types/pluginpb/plugin.pb.go | safe | This is a standard protoc-gen-go generated file for the well-known Google Protocol Buffers compiler plugin definitions, containing only benign message struct definitions, getters, and protobuf reflection registration with no malicious patterns. |
Scanned versions of google.golang.org/protobuf
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v1.36.12 | Needs review | 336 | Oct 5, 2026 |
Frequently asked questions
Is google.golang.org/protobuf safe to use?
No confirmed malware was found in google.golang.org/protobuf@v1.36.12, but the review flagged 4 medium, 18 low severity findings for risky patterns worth checking before you rely on it.
Does google.golang.org/protobuf contain malware?
No malware was identified in google.golang.org/protobuf@v1.36.12 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was google.golang.org/protobuf checked?
Togoder Security downloaded the published Go package and had an AI model read its 336 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan google.golang.org/protobuf together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in google.golang.org/protobuf@v1.36.12, cost nothing.